The environment was structured to separate research activity, Tor-routed traffic, sensitive credentials, untrusted content, and final reporting. Robin was deployed through Docker inside a dedicated research qube, with traffic routed through sys-whonix and sensitive notes stored separately in an offline vault qube. Disposable qubes were incorporated for opening potentially unsafe links and files.